Healthie logo

Security & Compliance Manager

Salary
$155K–$175K
Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Our Mission

Healthie is an AI-Native, ONC Certified EHR for modern outpatient healthcare.

Healthie is proud to power clinically excellent healthcare for over 40,000 providers who deliver clinically excellent healthcare - longitudinal and collaboratively, with patient and provider experiences at the center. Both healthcare and technology are undergoing unparalleled industry innovation, and it’s incredible to see the momentum - from consumers, from providers, and from reimbursement for this type of healthcare - grow exponentially.

We provide the powerful infrastructure every care delivery organization needs. On the surface this includes EHR, Scheduling, Engagement, Billing, Data, and much more. Underneath the iceberg are thousands of configurations, settings, widgets, automations, and limitless capabilities because we are an API-first platform. Our fully brandable platform makes it easy for clinics and organizations of any size to scale and never reach a limit.

Today, over 3 billion API calls are made to Healthie every month, as thousands of organizations who work with more than 21 million patients in total, rely on Healthie to deliver clinically excellent healthcare in over 35 specialties, from behavioral healthcare to complex chronic care management and personalized medicine.

We believe in the power of technology to improve access to healthcare and we’re building the rails that make this a reality. We work fast and with quality because we provide business-critical, healthcare-critical software that clinicians and patients need for a better healthcare system. We’re customer-obsessed, operate with lightning-fast processes and responses, and always share our product roadmap publicly- so customers can see what we’re building, and remain relentlessly focused on how care gets delivered.

Healthie is backed by leading investors, and while we've $42M raised to date, more importantly, we operate with fiscal responsibility and have been profitable for more than half of our time as a company. We know that building an ONC-Certified EHR is a lifetime’s body of work, and we are here to build for our customers forever.

Learn more at https://www.gethealthie.com/

About the role

As Manager, Security and Compliance, you'll run meaningful portions of the day-to-day security and compliance program at Healthie as a core member of Healthie’s Security and Compliance Team. You will own components of our audits, our third-party risk program, our customer-facing security work, and the policies and controls underneath all of it.

This is a builder's role. Some of what we need exists and needs to be run better. Some of it doesn't exist yet. You'll help decide what to fix first, design the process, pick or configure the tooling, and then run it until it works without you watching. You'll work with engineering, IT, operations, legal, sales, and the offices of the CEO and CTO, and report to Healthie’s VP of Security & Compliance. Many of the people you depend on won't report to you, so you'll need to get things done through influence and clear communication.

The work will include:

  • Our third-party audits, including SOC 2, the annual HIPAA assessment, and HITRUST. You will scope the work, assign evidence to control owners, and close findings.
  • Running the third-party risk management program. That covers vendor intake and tiering, security assessments, contract requirements such as BAAs, remediation tracking, and periodic reassessment. Vendors that touch PHI get the most attention.
  • Owning the customer trust function: security questionnaires, customer audits, trust center content, and security reviews during enterprise deals. You'll join sales calls when a prospect's security team wants to talk to someone who knows the answers, and you'll refine the existing answer library so most questionnaires never need you.
  • Contribute to the policy set, the control framework, and the risk register. You keep them accurate and mapped across frameworks, and you make sure people can follow them.
  • Administering Vanta and the workflows around it, so continuous monitoring actually leads to fixes instead of a growing list of failing tests.
  • Help with AI governance and data privacy practices. That includes reviews of AI features and AI vendors, privacy-by-design input on product work, and tracking state privacy laws, GDPR, and the EU AI Act as they apply to us.
  • Running intake and triage for every request that comes to security and compliance. You set the priorities, answer what you can, and route the rest to the right owner with a deadline.
  • Reporting program health to the VP and to leadership. You should be able to say where we are exposed, what is late, and what it will take to fix it.

What a quarter may look like: An audit in some phase of planning, fieldwork, or remediation. A dozen vendor reviews, two of which turn into real conversations about whether we should use that vendor at all. A handful of enterprise deals where security is on the critical path. One new process you are building from scratch, maybe an AI vendor review or a better reassessment cycle, and one existing process you are making faster. Somewhere in there, a policy update that needs sign-off from people who are busy.

You will have access to some of the company's most sensitive information, including data entrusted to our protection by customers and their clients. You must follow access rules exactly, raise your own mistakes before anyone else finds them, and keep confidence when it would be easier not to. At this level, other people will model their behavior on yours, so you set the standard.

This position will suit someone who has worked inside a security GRC or third-party risk team, ideally in healthcare or health tech, and has run pieces of a program rather than just supported them. Your background might be in IT, program management, privacy, or consulting. We care more about what you have built and run than about the path you took to get here.


About you

  • You must be based in the United States. (On occasion you may need to see protected health information [PHI], and our customers have contracts that forbid access to such information from outside the United States.)
  • You have roughly 7 or more years of professional experience, with at least 3 in security compliance, GRC, third-party risk, or privacy. You have owned a SOC 2 or HIPAA program, or a major part of one, at a company that handles regulated data.
  • You have built or rebuilt a process that other people now depend on. Third-party risk, audit readiness, questionnaire response, policy management: we don't mind which, as long as you can explain what you changed and why it worked.
  • You must be an excellent and fluent writer, speaker, and communicator in English, and able to do all of it without the aid of AI. You can compress a dense control requirement into two sentences a customer's security team will accept. You can write an exception that still holds up when someone audits it next year. And you can explain a risk to an executive without making it sound smaller or bigger than it is.
  • You understand the security and compliance challenges a modern healthcare software company faces, including the ones that come from customers, regulators, and the vendors we rely on.
  • You use AI as a working tool. You use it to draft documentation, map controls, and work through dense regulatory text, and you check its output before it goes anywhere. You can tell when a model is confidently wrong, and you would rather rewrite something than pass along slop. You also have opinions on how a company like ours should govern its own use of AI.
  • You can run a program across teams that do not report to you. You keep work organized and visible, you follow up without being asked, and people trust your plans because they tend to come true.
  • You are interested in software, technology, and its impact on humans. You ask why a control exists before you enforce it. You can find a workable answer when the framework does not give you one, and you understand why the person on the other end of a request is frustrated. Healthie's scope is large, and you will be asked how our technology fits the expectations of Healthie's customers and of their clients.
  • You can hold a position with executives, auditors, and customers when the requirement is clear, and change it when someone gives you a better reason. You know which decisions are yours to make and which ones to bring to the VP.

Nice to Have

  • Hands-on administration of modern GRC tooling such as Vanta, Drata, SecureFrame, or Thoropass.
  • Experience with third-party risk platforms such as OneTrust, or building a TPRM program on general work management tools.
  • Working knowledge of healthcare and privacy frameworks beyond HIPAA and SOC 2: HITRUST, NIST CSF, NIST AI RMF, ISO 27001, state privacy laws, GDPR, and the EU AI Act.
  • Experience inside a health system, payer, or health tech company that handles PHI at scale.
  • Any of CISA, CISM, CISSP, CIPP/US, CIPP/E, AIGP, or PMP. These are not required, and a narrow certification-driven background is not what we are looking for.


Details, details

  • This is a full-time, NYC-Hybrid position.
  • U.S. work authorization is required.
  • The salary for this position is a base between $155,000 - $175,000.


Interview Process

  • Quick chat with Katie from our Talent team (15 minutes)
  • Interview with John, VP Security & Compliance (30 minutes)
  • Talk with Edgar, Director of IT & Cindy, Director of People Operations: (30 minutes)
  • Interview with Sean, Staff AppSec Engineer(20 minutes)
  • Exec Interview with Cavan, CTO + cofounder (20 minutes)
  • Reference checks

Learn more at gethealthie.com/careers.

Healthie is subject to HIPAA and other security and privacy frameworks, and this job entails training and conformance to expectations regarding security and compliance.

Healthie participates in e-verify.

Healthie is committed to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. We're proud to be building a diverse and inclusive environment that encourages collaboration, creativity, and growth. Whatever your background, please apply if this is a role that would make you excited to come into work every day.

Similar jobs

Apply for this job